Visual detection of phishing websites via headless browser
Abstract
There is disclosed in one example a computing apparatus, including: a processor and a memory; a network interface; and instructions encoded within the memory to instruct the processor to: receive a uniform resource locator (URL) for analysis, the URL to access a web page via a remote server; via the network interface, retrieve from the remote server a copy of the web page; render the web page in a headless browser to provide a computer-accessible visual output; perform visual analysis of the visual output via a digital eye; compare the visual analysis to a plurality of known phishing target websites; and if the comparison identifies the web page as visually similar to a known phishing target website, detect the web page as a phishing web page.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method of detecting a phishing attack, comprising:
receiving an internet payload associated with a uniform resource locator (URL);
after determining that the URL does not use transport layer security (TLS) and has an unknown reputation, rendering the internet payload as a rendered payload image in a headless web browser;
using computer vision software to visually analyze the rendered payload image and determine that the rendered payload image is visually similar to a known legitimate website, wherein the computer vision software is a machine learning software trained on images of known legitimate websites;
determining that the internet payload is not associated with the known legitimate website; and
based on the determining, detecting the internet payload as a suspected phishing attack.
2. The method of claim 1 , wherein the internet payload is a website.
3. The method of claim 1 , wherein the internet payload is an email.
4. The method of claim 3 , wherein rendering the internet payload comprises rendering a webpage hosted at a link included within the email.
5. The method of claim 1 , wherein the internet payload is associated with a uniform resource locator (URL).
6. The method of claim 5 , further comprising determining a reputation for the URL, and considering the reputation for detecting the internet payload as a suspected phishing attack.
7. The method of claim 5 , further comprising querying a cloud-based URL reputation service for a reputation for the URL, and using computer vision based on determining that the reputation is below a threshold.
8. The method of claim 5 , further comprising querying a cloud-based URL reputation service for a reputation for the URL, and using computer vision based on determining that the reputation is unknown or unreliable.
9. The method of claim 5 , wherein determining that the internet payload is not associated with the known legitimate website comprises determining that the URL is not publicly associated with the known legitimate website.
10. The method of claim 1 , wherein using computer vision comprises first abstracting out some visual elements of the internet payload.
11. The method of claim 1 , further comprising assigning, to the internet payload, risk attributes before rendering the internet payload, and accounting for the risk attributes in detecting the internet payload as a suspected phishing attack.
12. The method of claim 11 , wherein assigning the risk attributes comprises assigning a risk based on determining that the internet payload is hosted on a hypertext transfer protocol (HTTP) domain without transport layer security (TLS).
13. The method of claim 11 , wherein assigning the risk attributes comprises assigning a risk based on determining that the internet payload targets or collects personally-identifying information (PII).
14. One or more tangible, non-transitory computer-readable storage media having stored thereon executable instructions to:
receive an internet payload associated with a uniform resource locator (URL);
after determining that the URL does not use transport layer security (TLS) and does not have a known reputation, render the internet payload as a rendered payload image in a headless web browser;
use computer vision software to visually analyze the rendered payload image and determine that the rendered payload image is visually similar to a known legitimate website, wherein the computer vision software is a machine learning software trained on images of known legitimate websites;
determine that the internet payload is not associated with the known legitimate website; and
based on the determining, detect the internet payload as a suspected phishing attack.
15. The one or more tangible, non-transitory computer-readable media of claim 14 , wherein the internet payload is associated with a uniform resource locator (URL).
16. The one or more tangible, non-transitory computer-readable media of claim 15 , wherein the instructions are further to determine a reputation for the URL, and consider the reputation for detecting the internet payload as a suspected phishing attack.
17. The one or more tangible, non-transitory computer-readable media of claim 15 , wherein the instructions are furtherer to query a cloud-based URL reputation service for a reputation for the URL, and use computer vision based on determining that the reputation is below a threshold.
18. The one or more tangible, non-transitory computer-readable media of claim 15 , wherein the instructions are further to query a cloud-based URL reputation service for a reputation for the URL, and use computer vision based on determining that the reputation is unknown or unreliable.
19. A computing apparatus, comprising:
a processor circuit and a memory; and
instructions encoded within the memory to instruct the processor circuit to:
receive an internet payload associated with a uniform resource locator (URL);
after determining that the URL does not have a known reputation and does not use transport layer security (TLS), render the internet payload as a rendered payload image in a headless web browser;
use computer vision software to visually analyze the rendered payload image and determine that the rendered payload image is visually similar to a known legitimate website, wherein the computer vision software is a machine learning software trained on known legitimate websites;
determine that the internet payload is not associated with the known legitimate website; and
based on the determining, detect the internet payload as a suspected phishing attack.
20. The computing apparatus of claim 19 , wherein the computing apparatus is a home or enterprise gateway.Join the waitlist — get patent alerts
Track US12069091B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.